|
210061
|
5.4 |
MEDIUM
Network
|
edx
|
open_edx_platform
|
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13145
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210062
|
8.8 |
HIGH
Network
|
edx
|
open_edx_platform
|
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Pyth…
|
CWE-94 CWE-862
Code Injection Missing Authorization
|
CVE-2020-13144
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210063
|
6.5 |
MEDIUM
Network
|
linux opensuse debian canonical netapp
|
linux_kernel leap debian_linux ubuntu_linux cloud_backup element_software steelstore_cloud_integrated_storage solidfire hci_management_node active_iq_unified_manager sol…
|
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attack…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-13143
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210064
|
7.5 |
HIGH
Network
|
dlink
|
dsp-w215_firmware
|
D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer.
|
NVD-CWE-noinfo
|
CVE-2020-13136
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210065
|
6.5 |
MEDIUM
Adjacent
|
dlink
|
dsp-w215_firmware
|
D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstrated by a Squid Proxy.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-13135
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210066
|
5.3 |
MEDIUM
Network
|
libreoffice opensuse
|
libreoffice leap
|
If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-12801
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210067
|
7.2 |
HIGH
Network
|
heinekingmedia
|
stashcat
|
An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms. The GET method is used with client_key and device_id data in the query string…
|
CWE-200
Information Exposure
|
CVE-2020-13129
|
2024-11-21 14:00 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210068
|
5.3 |
MEDIUM
Network
|
health
|
covidsafe
|
COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows for re-identificatio…
|
CWE-269
Improper Privilege Management
|
CVE-2020-12860
|
2024-11-21 14:00 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210069
|
5.3 |
MEDIUM
Network
|
health
|
covidsafe
|
Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify a device model by observing cleartext payload data. This allows re-identificati…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-12859
|
2024-11-21 14:00 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210070
|
7.5 |
HIGH
Network
|
health
|
covidsafe
|
Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to re-identify Android devices running COVIDSafe by scanning for their adverti…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-12858
|
2024-11-21 14:00 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|